VYPR

Qts

by Qnap

CVEs (287)

  • CVE-2014-7169CriKEVSep 25, 2014
    risk 0.87cvss 9.8epss 1.00

    GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by…

  • CVE-2014-6271CriKEVSep 24, 2014
    risk 0.87cvss 9.8epss 1.00

    GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd,…

  • CVE-2018-19949CriKEVOct 28, 2020
    risk 0.84cvss 9.8epss 0.24

    If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS…

  • CVE-2019-7193CriKEVDec 5, 2019
    risk 0.83cvss 9.8epss 0.14

    This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP recommend updating QTS to their latest versions.

  • CVE-2020-2509CriKEVApr 17, 2021
    risk 0.78cvss 9.8epss 0.33

    A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. We have already fixed this vulnerability in the following versions: QTS 4.5.2.1566 Build…

  • CVE-2017-6360CriMar 23, 2017
    risk 0.72cvss 9.8epss 0.66

    QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and obtain sensitive information via unspecified vectors.

  • CVE-2018-19943HigKEVOct 28, 2020
    risk 0.71cvss 8.0epss 0.18

    If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in the following QTS versions. QTS 4.4.2.1270 build 20200410 and later QTS 4.4.1.1261 build 20200330 and later QTS 4.3.6.1263 build…

  • CVE-2017-6361CriMar 23, 2017
    risk 0.71cvss 9.8epss 0.57

    QNAP QTS before 4.2.4 Build 20170313 allows attackers to execute arbitrary commands via unspecified vectors.

  • CVE-2017-6359CriMar 23, 2017
    risk 0.69cvss 9.8epss 0.27

    QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and execute arbitrary commands via unspecified vectors.

  • CVE-2017-13067CriSep 14, 2017
    risk 0.68cvss 9.8epss 0.17

    QNAP has patched a remote code execution vulnerability affecting the QTS Media Library in all versions prior to QTS 4.2.6 build 20170905 and QTS 4.3.3.0299 build 20170901. This particular vulnerability allows a remote attacker to execute commands on a QNAP NAS using a…

  • CVE-2024-21899CriMar 8, 2024
    risk 0.66cvss 9.8epss 0.24

    An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have already fixed the vulnerability in the following…

  • CVE-2024-32766CriApr 26, 2024
    risk 0.65cvss 10.0epss 0.02

    An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build…

  • CVE-2023-23368CriNov 3, 2023
    risk 0.65cvss 9.8epss 0.19

    An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2376 build…

  • CVE-2017-7876CriJun 15, 2017
    risk 0.65cvss 10.0epss 0.03

    This command injection vulnerability in QTS allows attackers to run arbitrary commands in the compromised application. QNAP have already fixed the issue in QTS 4.2.6 build 20170517, QTS 4.3.3.0174 build 20170503 and later versions.

  • CVE-2025-66276CriJun 10, 2026
    risk 0.64cvss 9.8epss 0.00

    QuTS hero is not affected. We have already fixed the vulnerability in the following version: QTS 5.2.7.3256 build 20250913 and later

  • CVE-2025-66277CriFeb 11, 2026
    risk 0.64cvss 9.8epss 0.01

    A link following vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to traverse the file system to unintended locations. We have already fixed the vulnerability in the following versions: QTS…

  • CVE-2025-62849CriDec 16, 2025
    risk 0.64cvss 9.8epss 0.01

    An SQL injection vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3297…

  • CVE-2025-59385CriDec 16, 2025
    risk 0.64cvss 9.8epss 0.01

    An authentication bypass by spoofing vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to access resources which are not otherwise accessible without proper authentication. We have already…

  • CVE-2024-50393CriDec 6, 2024
    risk 0.64cvss 9.8epss 0.01

    A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954…

  • CVE-2022-27596CriJan 30, 2023
    risk 0.64cvss 9.8epss 0.03

    A vulnerability has been reported to affect QNAP device running QuTS hero, QTS. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of QuTS hero, QTS: QuTS hero h5.0.1.2248 build…

Page 1 of 15